Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

when installing applications does windows store who the identity of the user who instlled it?

Posted on 2014-12-20
11
Medium Priority
?
80 Views
Last Modified: 2015-01-08
Hi

In a scenario where admin rights are required to install software and the user has no admin rights, a user with the rights can right click on the setup and select 'run as a different user'... which allows you to install the application using another identity.


Is it possible to check who installed the said application?  If so, how?

Thanks
0
Comment
Question by:cycledude
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 56

Accepted Solution

by:
McKnife earned 2000 total points
ID: 40510778
In eventviewer, you can visit the application log and filter for Event ID 1033. There you can see who installed. This is true for windows installer packages, I am not sure how to find it for other installers like nullsoft or install shield.
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40510797
The software itself keeps track of who installed it and who is running it. So Office (for example) needs to be set up by each user, but it will know who is the owner. This is especially true for Office 2013 which runs by subscription.

Other software I have know the installer and the user.

I am not sure how you can find it (the values are probably all over the registry).
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40510814
Here is an example. ME is a driver on my Windows 8 machine that has a user interface. It knows I installed it.

Also, look at software installs:  Install for "Me" or for "Everyone" .

Windows-8-Installer-Name
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 56

Expert Comment

by:McKnife
ID: 40510819
Your screenshot shows that it knows you installed it? Well, it lists the source of the installer file (which used your temp directory), that's all, it could have been anyone, although this is at least an indicator.
No, softwares usually don't keep track themselves of who installed them. Identifying that will only be possible through installer logging like I showed for windows installer.
This is a security topic, I have looked into that years ago.
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40510830
Point taken. As I noted I do not know exactly where by application.

Here is the setup section for Companionlink that knows me as the owner of the product and I think also as the installer.

Windows-8-Installer-Name2
I install stuff in my Windows 7 or Windows 8 userid which is an administrator ID. When I log into Administrator and try to run some software, it barks at me because it needs to be registered again. Not all software but some.
0
 
LVL 56

Expert Comment

by:McKnife
ID: 40510841
The info shown is what you provided voluntarily. It was not retrieved by setup programatically, so it cannot be used to find out what user installed something.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40511395
Also If I am not mistaken, the question actually means....

If USER A has to use elevated permissions by using RUNAS another user, can I tell what they installed?

The answer to that question is NO.  The installer will only know about the elevated user and not about USER A.

If you open a command prompt by doing RUNAS another user, you are in effect logging into windows as that other user and opening a command prompt. It knows nothing of the USER A.
0
 
LVL 56

Expert Comment

by:McKnife
ID: 40511619
Right, Neilsr, that was what has been asked.
So the runas impersonation needs to be logged, too - "who impersonated the admin" is the big question. That will be answered by windows security log. The default auditing settings don't log that, I think, at least not on standalone computers.
So enable "audit logon events" in secpol.msc ->local policies ->audit policy
Then, you will find log entries for impersonation events, just search for "impersonation".

But, it's not that easy. If the weak user uses runas.exe, it will be logged, you can easily see that it was weakuser who impersonated adminuser. But: If he just starts a setup and the UAC prompts for admin credentials, then it is not the user himself who invokes the impersonation but it is the system account (pcname$), because the UAC prompt is started by the OS itself. So then you will not be able to see directly who impersonates the adminuser. So your solution will be:

Enable the aforementioned logging and look for impersonation events. Then find out who was logged in at the time the impersonation event took place.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40511664
And that's no use to you unless you are checking the logs all the time or have a
Mechanism for storing the log permanently.
It is no good to you six months time asking "Who installed xyz on that machine?"
0
 
LVL 56

Expert Comment

by:McKnife
ID: 40511702
You don't check the logs manually but setup event triggers. Those trigger tasks that use powershell to filter and send alerts. Try it, works wonderful. Can be deployed via GPO, too.
0
 

Author Closing Comment

by:cycledude
ID: 40538341
thanks ;o)
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the features I've come to appreciate about Windows 7 and Windows Server 2008 R2 is the ability to pin applications to the task bar. As useful a feature as I've found this, it does have some quirks.  For example, have you ever tried pinning an…
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question